Bugpoint
1.05K subscribers
3.73K photos
3.73K links
Latest updates about disclosure bug bounty reports: tech details, impacts, bounties πŸ“£

RateπŸ‘‡
https://cutt.ly/bugpoint_rate
FeedbackπŸ‘‡
https://cutt.ly/bugpoint_feedback

#️⃣ bug bounty disclosed reports
#️⃣ bug bounty write-ups
#️⃣ bug bounty teleg
Download Telegram
SQL injection at [β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ] [HtUS]

πŸ‘‰ https://hackerone.com/reports/1626198

πŸ”Ή Severity: Critical | πŸ’° 1,000 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #malcolmx
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 9:06pm (UTC)
time based SQL injection at [https://β–ˆβ–ˆβ–ˆ] [HtUS]

πŸ‘‰ https://hackerone.com/reports/1627970

πŸ”Ή Severity: Critical | πŸ’° 1,000 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #malcolmx
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 9:10pm (UTC)
πŸ”₯1
STORED XSS in β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆ/nlc/login.aspx via "edit" GET parameter through markdown editor [HtUS]

πŸ‘‰ https://hackerone.com/reports/1631447

πŸ”Ή Severity: High
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #shreky
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 14, 2022, 9:13pm (UTC)
No validation to Image upload user can upload ( php APK zip files and can be used as storage purpose)

πŸ‘‰ https://hackerone.com/reports/1644062

πŸ”Ή Severity: Medium | πŸ’° 750 USD
πŸ”Ή Reported To: Linktree
πŸ”Ή Reported By: #bug_vs_me
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 15, 2022, 5:38am (UTC)
[hta3] Remote Code Execution on https://β–ˆβ–ˆβ–ˆ via improper access control to SCORM Zip upload/import

πŸ‘‰ https://hackerone.com/reports/1122791

πŸ”Ή Severity: Critical | πŸ’° 2,000 USD
πŸ”Ή Reported To: U.S. Dept Of Defense
πŸ”Ή Reported By: #cdl
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 15, 2022, 1:28pm (UTC)
πŸ‘1
store internal email disclosed through shopify-data-exporter

πŸ‘‰ https://hackerone.com/reports/1605962

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Shopify
πŸ”Ή Reported By: #xenx
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 15, 2022, 7:21pm (UTC)
Information exposure in in guzzlehttp/guzzle (https://github.com/nextcloud/3rdparty/tree/master/guzzlehttp/guzzle)

πŸ‘‰ https://hackerone.com/reports/1604606

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #ro0telqayser
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 16, 2022, 2:52am (UTC)
Last video frame is still sent after video is disabled in a call

πŸ‘‰ https://hackerone.com/reports/1641088

πŸ”Ή Severity: Medium
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #daniel_calvino_sanchez
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 16, 2022, 4:52am (UTC)
SSRF via potential filter bypass with too lax local domain checking

πŸ‘‰ https://hackerone.com/reports/1608039

πŸ”Ή Severity: Low
πŸ”Ή Reported To: Nextcloud
πŸ”Ή Reported By: #tomorrowisnew_
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 16, 2022, 5:00am (UTC)
XSS in www.glassdoor.com

πŸ‘‰ https://hackerone.com/reports/1695989

πŸ”Ή Severity: Medium | πŸ’° 500 USD
πŸ”Ή Reported To: Glassdoor
πŸ”Ή Reported By: #seifelsallamy
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 16, 2022, 8:10pm (UTC)
Airflow Daemon Mode Insecure Umask Privilege Escalation

πŸ‘‰ https://hackerone.com/reports/1690093

πŸ”Ή Severity: Medium | πŸ’° 2,400 USD
πŸ”Ή Reported To: Internet Bug Bounty
πŸ”Ή Reported By: #nyymi
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 17, 2022, 12:23pm (UTC)
HTML Injection in email via Name field

πŸ‘‰ https://hackerone.com/reports/1581499

πŸ”Ή Severity: Low | πŸ’° 500 USD
πŸ”Ή Reported To: HackerOne
πŸ”Ή Reported By: #mega7
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 18, 2022, 9:24am (UTC)
There is no rate limit for SME REGISTRATION PORTAL

πŸ‘‰ https://hackerone.com/reports/1305766

πŸ”Ή Severity: No Rating
πŸ”Ή Reported To: MTN Group
πŸ”Ή Reported By: #sachinrajput
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 19, 2022, 5:41am (UTC)
CORS Misconfiguration on vanillaforums.com

πŸ‘‰ https://hackerone.com/reports/1527555

πŸ”Ή Severity: Medium | πŸ’° 150 USD
πŸ”Ή Reported To: Vanilla
πŸ”Ή Reported By: #admin0x00
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 20, 2022, 4:34pm (UTC)
Use-after-free in setsockopt IPV6_2292PKTOPTIONS (CVE-2020-7457)

πŸ‘‰ https://hackerone.com/reports/1441103

πŸ”Ή Severity: High | πŸ’° 10,000 USD
πŸ”Ή Reported To: PlayStation
πŸ”Ή Reported By: #theflow0
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 20, 2022, 9:16pm (UTC)
πŸ‘1
IDOR on Tagged People

πŸ‘‰ https://hackerone.com/reports/1555376

πŸ”Ή Severity: Medium | πŸ’° 3,000 USD
πŸ”Ή Reported To: TikTok
πŸ”Ή Reported By: #apapedulimu
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 20, 2022, 10:17pm (UTC)
πŸ‘1
DOS: out of memory from gif through upload api

πŸ‘‰ https://hackerone.com/reports/1620170

πŸ”Ή Severity: Low | πŸ’° 150 USD
πŸ”Ή Reported To: Mattermost
πŸ”Ή Reported By: #catenacyber
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 21, 2022, 8:49am (UTC)
size_t-to-int vulnerability in exFAT leads to memory corruption via malformed USB flash drives

πŸ‘‰ https://hackerone.com/reports/1340942

πŸ”Ή Severity: High | πŸ’° 10,000 USD
πŸ”Ή Reported To: PlayStation
πŸ”Ή Reported By: #theflow0
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 21, 2022, 7:06pm (UTC)
πŸ”₯3
Create product discounts of any shop

πŸ‘‰ https://hackerone.com/reports/1571578

πŸ”Ή Severity: Medium | πŸ’° 4,500 USD
πŸ”Ή Reported To: TikTok
πŸ”Ή Reported By: #datph4m
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 21, 2022, 10:39pm (UTC)
Add products to any livestream.

πŸ‘‰ https://hackerone.com/reports/1654657

πŸ”Ή Severity: Medium | πŸ’° 3,000 USD
πŸ”Ή Reported To: TikTok
πŸ”Ή Reported By: #datph4m
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 21, 2022, 10:41pm (UTC)
DLL Search-Order Hijacking Vulnerability in work-64-exe-v7.16.3-1.exe

πŸ‘‰ https://hackerone.com/reports/1519437

πŸ”Ή Severity: Low
πŸ”Ή Reported To: 8x8
πŸ”Ή Reported By: #is-
πŸ”Ή State: 🟒 Resolved
πŸ”Ή Disclosed: September 22, 2022, 3:19am (UTC)